Annke produces surveillance and network camera systems, with vulnerabilities observed across firmware components for products such as the Crater 2 and N48PBB device lines. The exposure pattern centers on web-interface and OS-command handling weaknesses including cross-site scripting, OS command injection, buffer overflows, and out-of-bounds writes, reflecting the embedded firmware and remote-management attack surface inherent to networked security appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Annke over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32941CRITICAL Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attack | May 23, 2022 | 9.8 | 39 | NO | NO |
CVE-2024-39091HIGH An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary | Aug 12, 2024 | 8.8 | 27 | NO | NO |
CVE-2017-18483MEDIUM ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID. | Aug 7, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Annke.
Media articles that mention a CVE ID that affects a product developed by Annke — matched by CVE ID, not by vendor name.